Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CL-CRI-1116

Description

Since February 2026, multiple incidents involving data theft and extortion have been attributed to activity cluster CL-CRI-1116, also known as BlackFile, UNC6671, and Cordial Spider. These financially-motivated attackers, likely associated with "The Com" collective, employ voice-based phishing combined with credential harvesting through fraudulent login pages. They impersonate IT support staff to steal credentials and bypass multi-factor authentication. The attackers focus on Living Off the Land techniques, abusing legitimate APIs like Microsoft Graph to access SharePoint sites and Salesforce data. They search for confidential information and employee data within SaaS environments, then exfiltrate it through browser downloads or API exports. To pressure victims into paying seven-figure ransoms, attackers send demands via Gmail and compromised email accounts, sometimes employing SWATting tactics against executives.

Goals & Targeting

Targeted Sectors

Retail
Information technology

AI Analysis

· 2 months ago

Executive Summary

The group's activities have resulted in multiple incidents of data theft and extortion, with demands for significant ransoms. Their operations are characterized by a high level of sophistication and adaptability, making them a challenging threat to detect and respond to. As such, organizations in the retail and information technology sectors must remain vigilant and take proactive measures to protect themselves against this and similar threats.

Enhanced Description

In terms of the threat actor's motivations and goals, it is clear that financial gain is the primary driver of their activities. The group's use of extortion and ransom demands is a key aspect of their modus operandi, and they appear to be willing to use a range of tactics to achieve their objectives. This includes the use of SWATting tactics against executives, which creates a sense of urgency and fear, and can put significant pressure on organizations to pay the demanded ransom. The fact that the group is willing to use such tactics highlights the ruthless nature of their operations and the need for organizations to be prepared to respond quickly and effectively in the event of an attack.

Key Capabilities

  • Voice-based phishing
  • Credential harvesting
  • Abuse of legitimate APIs
  • Living Off the Land techniques
  • Data exfiltration through browser downloads or API exports
  • Ransom demands via email and SWATting tactics

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

Recommended Actions

  • Implement robust security measures to protect against voice-based phishing and credential harvesting
  • Monitor and control access to sensitive data and systems, particularly in cloud-based environments
  • Implement advanced threat detection and response strategies to detect and prevent LOTL techniques
  • Educate employees on the risks associated with phishing attacks and the importance of robust authentication and authorization mechanisms
  • Regularly review and update incident response plans to prepare for potential attacks

Suggested Tags

APT
Ransomware
Extortion
Data Theft
Phishing
Cloud Security

Confidence Assessment

The confidence level in the available data is moderate to high, based on multiple reported incidents and technical analysis of the threat actor's tactics, techniques, and procedures (TTPs). However, there may be some uncertainty regarding the group's exact motivations, relationships with other threat actors, and the full scope of their operations.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

32

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Phishing
Data Exfiltration

Details

Type
Apt
Confidence
50%
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.